MySQL - 锁定用户账户



MySQL 中引入账户锁定是为了通过防止未经授权的事务或可疑活动来提高数据库的安全性。

在许多情况下,MySQL 用户账户需要出于各种原因被锁定。例如,在完成账户授权之前等待,或者如果账户长时间处于非活动状态等。在这种情况下,锁定账户将提高 MySQL 服务器的效率。

MySQL 锁定用户账户

要检查账户是否被锁定,MySQL 在 'mysql.user' 表中提供了 'account_locked' 属性,该属性将分别保存 'Y' 或 'N' 值。值 'Y' 表示账户已锁定,而 'N' 表示账户未锁定。

锁定新账户

MySQL 提供 ACCOUNT LOCK 子句来锁定账户。将此子句与 CREATE USER 和 ALTER USER 语句一起使用,将分别创建新的已锁定用户或锁定现有用户。

语法

以下是 CREATE USER... ACCOUNT LOCK 语句的语法:

CREATE USER username@hostname 
IDENTIFIED BY 'new_password' ACCOUNT LOCK;

示例

在以下查询中,我们使用 CREATE USER 语句在 MySQL 中创建一个新的已锁定用户账户:

CREATE USER test@localhost IDENTIFIED BY 'asdfgh' ACCOUNT LOCK;

输出

以下是上述代码的输出:

Query OK, 0 rows affected (0.02 sec)

验证

我们可以使用以下 SELECT 语句验证 'test' 用户的账户是否被锁定:

SELECT User, Host, account_locked 
FROM mysql.user WHERE User = 'test';

上述代码的输出如下所示:

用户 主机 account_locked
test localhost Y

由于账户被锁定,除非再次解锁,否则您无法访问它。请参阅以下示例:

C:\Windows\System32> mysql -u test -p
Enter password: ******

产生的结果如下:

ERROR 3118 (HY000): Access denied for user 'test'@'localhost'. Account is locked.

锁定现有账户

我们可以使用 ALTER USER... ACCOUNT LOCK 语句来锁定 MySQL 中的现有账户。但您必须确保在执行查询之前用户处于解锁状态。

语法

以下是 ALTER USER... ACCOUNT LOCK 语句的语法:

ALTER USER username@hostname ACCOUNT LOCK;

示例

在这里,我们使用 ALTER USER 语句锁定 MySQL 中的现有用户账户:

ALTER USER sample@localhost ACCOUNT LOCK;

输出

上述代码的输出如下所示:

Query OK, 0 rows affected (0.00 sec)

验证

我们可以使用以下 SELECT 语句验证 'sample' 用户的账户是否被锁定:

SELECT User, Host, account_locked 
FROM mysql.user WHERE User = 'sample';

获得的结果如下所示:

用户 主机 account_locked
sample localhost Y

为了验证账户是否被锁定,让我们像下面查询中所示的那样访问它:

C:\Windows\System32> mysql -u sample -p
Enter password: ******

我们得到以下输出:

ERROR 3118 (HY000): Access denied for user 'sample'@'localhost'. Account is locked.

使用客户端程序锁定用户账户

现在,在本节中,让我们讨论如何使用各种客户端程序锁定 MySQL 用户。

语法

以下是语法:

以下是使用 PHP 锁定 MySQL 用户账户的语法:

$sql = "CREATE USER user_name IDENTIFIED BY 'password' ACCOUNT LOCK";
Or,
$sql = "ALTER USER user_name@localhost IDENTIFIED BY 'password' ACCOUNT LOCK";
$mysqli->query($sql);

以下是使用 JavaScript 锁定 MySQL 用户账户的语法:

sql= "CREATE USER username@hostname IDENTIFIED BY 'new_password' ACCOUNT LOCK";
con.query(sql, function (err, result) {
   if (err) throw err;
      console.log(result);
});

以下是使用 Java 锁定 MySQL 用户账户的语法:

String sql = "ALTER USER USER_NAME@LOCALHOST IDENTIFIED BY 'password' ACCOUNT LOCK";
Or,
String sql = "CREATE USER USER_NAME IDENTIFIED BY 'password' ACCOUNT LOCK";
statement.execute(sql);

以下是使用 Python 锁定 MySQL 用户账户的语法:

sql = f"ALTER USER '{username_to_lock}'@'localhost' ACCOUNT LOCK";
cursorObj.execute(sql);

示例

以下是各种编程语言中锁定用户的程序:

$dbhost = 'localhost';
$dbuser = 'root';
$dbpass = 'password';
$mysqli = new mysqli($dbhost, $dbuser, $dbpass);
   if($mysqli->connect_errno ) {
   printf("Connect failed: %s
", $mysqli->connect_error); exit(); } //printf('Connected successfully.
'); $sql = "CREATE USER Sarika IDENTIFIED BY 'password' ACCOUNT LOCK;"; if($mysqli->query($sql)){ printf("User has been locked successfully..!"); } if($mysqli->error){ printf("Failed..!" , $mysqli->error); } $mysqli->close();

输出

获得的输出如下所示:

User has been locked successfully..!
var mysql = require('mysql2');
var con = mysql.createConnection({
    host: "localhost",
    user: "root",
    password: "Nr5a0204@123"
});

  //Connecting to MySQL
  con.connect(function (err) {
  if (err) throw err;
  console.log("Connected!");
  console.log("--------------------------");

  sql = "CREATE USER test@localhost IDENTIFIED BY 'asdfgh' ACCOUNT LOCK;"
  con.query(sql);

  sql = "SELECT User, Host, account_locked FROM mysql.user WHERE User = 'test';";
  con.query(sql, function(err, result){
    if (err) throw err;
    console.log(result);
  });
});

输出

产生的输出如下所示:

Connected!
--------------------------
[ { User: 'test', Host: 'localhost', account_locked: 'Y' } ]
import java.sql.Connection;
import java.sql.DriverManager;
import java.sql.Statement;
public class LockUserAccount {
	public static void main(String[] args) {
		String url = "jdbc:mysql://127.0.0.1:3306/TUTORIALS";
		String user = "root";
		String password = "password";
		try {
			Class.forName("com.mysql.cj.jdbc.Driver");
            Connection con = DriverManager.getConnection(url, user, password);
            Statement st = con.createStatement();
            //System.out.println("Database connected successfully...!");
            String sql = "ALTER USER Vivek@localhost IDENTIFIED BY 'password' ACCOUNT LOCK";
            st.execute(sql);
            System.out.println("User 'Vivek' account locked successfully...!");    
		}catch(Exception e) {
			e.printStackTrace();
		}
	}
}

输出

获得的输出如下所示:

User 'Vivek' account locked successfully...!
import mysql.connector
# creating the connection object
connection = mysql.connector.connect(
    host='localhost',
    user='root',
    password='password'
)
username_to_lock = 'newUser'
# Create a cursor object for the connection
cursorObj = connection.cursor()
cursorObj.execute(f"ALTER USER '{username_to_lock}'@'localhost' ACCOUNT LOCK")
print(f"User '{username_to_lock}' account is locked successfully.")
cursorObj.close()
connection.close()

输出

以下是上述代码的输出:

User 'newUser' account is locked successfully.
广告